Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-18422
HistoryMar 07, 2022 - 12:00 a.m.

Grafana Cross-Site Request Forgery Vulnerability

2022-03-0700:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.004 Low

EPSS

Percentile

72.4%

Grafana is an open source monitoring tool from Grafana Labs that provides a visual monitoring interface. The tool is primarily used to monitor and analyze Graphite, InfluxDB, Prometheus, etc. A cross-site request forgery vulnerability exists in Grafana, which stems from the product’s failure to adequately verify that requests come from trusted users. An attacker could exploit the vulnerability to escalate privileges.